CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-55497 MEDIUM
Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)
CVSS 6.5
CVE-2026-14539 MEDIUM
Denial of Service via Unrestricted Payload Buffering in MCP Toolbox
CVE-2026-12733 HIGH
IBM DataPower Gateway affected by denial of service
CVSS 7.5
CVE-2026-16308 HIGH
IBM Enterprise Build of Quarkus is affected by a DoS vulnerability
CVSS 7.5
CVE-2026-11897 HIGH
IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2
CVSS 7.5
CVE-2026-18362 MEDIUM
DFIR-IRIS Missing Brute Force Protection in User Authentication
CVSS 5.9
CVE-2026-16971 MEDIUM
DFIR-IRIS Missing Brute Force Protection in OTP Validation
CVSS 5.9
CVE-2026-67437 HIGH
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
CVSS 7.5
CVE-2026-67432 HIGH
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
CVSS 7.5
CVE-2026-67430 MEDIUM
MCP Ruby SDK < 0.23.0 - StreamableHTTPTransport Memory Exhaustion
CVSS 5.3
CVE-2026-63119 MEDIUM
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
CVSS 6.2
CVE-2026-15975 HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2026-59899 MEDIUM
Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
CVE-2026-15144 HIGH
@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation
CVSS 7.3
CVE-2026-54638 HIGH
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
CVSS 7.5
CVE-2026-54609 HIGH
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVSS 8.6
CVE-2026-54345 MEDIUM
gopacket < 1.6.1 - Diameter AVP Integer Underflow Denial of Service
CVE-2026-54332 MEDIUM
Gopacket < 1.6.1 - Denial of Service
CVE-2026-61609 HIGH
Pterodactyl Panel >= 1.7.0, < 1.13.0 - Auth Rate-Limit Denial of Service
CVSS 7.5
CVE-2026-47483 HIGH
Nvidia Dcgm - Allocation of Resources Without Limits or Throttling
CVSS 8.2
CVE-2026-65624 MEDIUM
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion
CVE-2026-59248 HIGH
Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS
CVE-2026-64646 MEDIUM
Next.js: Unbounded Server Action payload in Edge runtime
CVSS 5.3
CVE-2026-59251 HIGH
Denial of service via exponential certificate policy tree growth in path validation
CVE-2026-42792 MEDIUM
epmd permanent DoS via EMFILE on accept(2) in erts
Details
Vulnerabilities 2,071
Exploit Likelihood High